Remote Code Execution Vulnerability in Internet Explorer on Windows XP and Older Versions
CVE-2004-0839

Currently unrated

Key Information:

Vendor
Avaya
Vendor
CVE Published:
18 August 2004

Summary

A vulnerability in Internet Explorer, specifically in versions such as 5.01 and 5.5, as well as Windows XP SP2, permits remote attackers to execute arbitrary code on users' systems. This can be achieved through specially crafted web pages that leverage specific CSS styles, the AnchorClick behavior, and drag-and-drop features to silently drop malicious executables into the user's local startup folder, thereby executing them upon system startup. To mitigate this issue, users are advised to apply updates from Microsoft and adhere to best practices in web security.

References

EPSS Score

38% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.
CVE-2004-0839 : Remote Code Execution Vulnerability in Internet Explorer on Windows XP and Older Versions | SecurityVulnerability.io